Files
WELA/config/event_measurement.json
田中ザック Isaac Mathis 2fd37d0318 Measure bounded native event delivery and verify exact EVTX samples (#430)
* Add bounded local delivery measurement and exact EVTX samples

* Link delivery measurement changelog to PR 430

* Reject evidence aliases before Windows path normalization

* Use PowerShell 5.1-compatible record IDs and bound fixture cleanup

* Revalidate the native EVTX artifact before recording final evidence

* Require exact observed local computer identities for sampled events

* Clarify provider scope within shared built-in event channels

* Preserve mixed XML payload ordering in EVTX sample verification

* Bound ordered event XML comparisons for nested UserData

* Dispose observer wait handle when bookmark creation fails
2026-09-21 09:14:48 +09:00

16 lines
756 B
JSON

{
"schemaVersion": 1,
"kind": "WelaLocalDeliveryMeasurement",
"channels": [
"Security",
"System",
"Application",
"Microsoft-Windows-DNS-Client/Operational",
"Microsoft-Windows-CAPI2/Operational",
"Microsoft-Windows-WinRM/Operational",
"Microsoft-Windows-PowerShell/Operational"
],
"source": "https://learn.microsoft.com/en-us/windows/win32/api/winevt/nf-winevt-evtsubscribe",
"scope": "Exact registered local Administrative/Operational channels only. ForwardedEvents, Analytic/Debug and third-party channels are excluded. Shared built-in channels may contain records from non-Microsoft providers; actual provider identity is retained. Registration, availability and reader access are verified on the actual host."
}